The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2012-01-08T15:00:00Z
Updated: 2024-09-16T22:24:46.401Z
Reserved: 2012-01-08T00:00:00Z
Link: CVE-2012-0393
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-01-08T15:55:01.420
Modified: 2024-11-21T01:34:53.817
Link: CVE-2012-0393
Redhat